The package includes tests, a useful README, a matching repository, and an MIT license. Its one-person ownership and install-time project script add maintenance and installation risk.
43%
Total Score
50
78
50
The package has had four releases, all concentrated in November 2017, with no releases in the last nine years. That long release gap is strong evidence of abandonment risk for a dependency.
The post-create-project-cmd script runs during Composer project creation. This is plausible for a CLI application scaffold, but it adds install-time behavior that consumers should account for.
Only one registry publishing account is listed. That is not inherently unhealthy for a user-owned project, but combined with the long release gap it indicates limited maintenance capacity.
The repository is owned by the same individual namespace as the package, with user ownership rather than organizational backing. This is consistent ownership but provides no broader maintenance capacity.
The repository has one star and no forks, providing little evidence of community adoption or backup maintenance. Popularity is supporting evidence rather than a verdict by itself.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
vlucas/phpdotenv Version ^2.4 | — | — |
laravel-zero/framework Version 4.0.* | — | — |
giggsey/libphonenumber-for-php Version ^8.8 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.